2008-12-25 03:25:13 +00:00
|
|
|
. /etc/functions.sh
|
|
|
|
include /lib/network
|
|
|
|
scan_interfaces
|
|
|
|
|
|
|
|
upnp_ipt() {
|
|
|
|
iptables "$@" 2>/dev/null
|
|
|
|
}
|
|
|
|
|
|
|
|
upnp_firewall_addif() {
|
2009-01-14 23:18:45 +00:00
|
|
|
local extif
|
|
|
|
local extip
|
|
|
|
local iface
|
2008-12-25 03:25:13 +00:00
|
|
|
|
|
|
|
config_load upnpd
|
2009-01-14 23:18:45 +00:00
|
|
|
config_get iface config external_iface
|
|
|
|
|
|
|
|
[ -n "$INTERFACE" -a "$INTERFACE" != "$iface" ] && return
|
2008-12-25 03:25:13 +00:00
|
|
|
|
|
|
|
config_load network
|
2009-01-14 23:18:45 +00:00
|
|
|
config_get extip "${iface:-wan}" ipaddr
|
|
|
|
config_get extif "${iface:-wan}" ifname
|
|
|
|
|
|
|
|
logger -t "upnp firewall" "adding wan interface $extif($extip)"
|
|
|
|
|
|
|
|
upnp_ipt -t nat -N miniupnpd_${iface:-wan}_rule
|
|
|
|
upnp_ipt -t nat -A miniupnpd_${iface:-wan}_rule -i $extif -d $extip -j MINIUPNPD
|
|
|
|
upnp_ipt -t nat -A prerouting_rule -j miniupnpd_${iface:-wan}_rule
|
2008-12-25 03:25:13 +00:00
|
|
|
|
2009-01-14 23:18:45 +00:00
|
|
|
upnp_ipt -t filter -N miniupnpd_${iface:-wan}_rule
|
|
|
|
upnp_ipt -t filter -A miniupnpd_${iface:-wan}_rule -i $extif -o ! $extif -j MINIUPNPD
|
|
|
|
upnp_ipt -t filter -A forwarding_rule -j miniupnpd_${iface:-wan}_rule
|
2008-12-25 03:25:13 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
upnp_firewall_delif() {
|
2009-01-14 23:18:45 +00:00
|
|
|
local iface
|
|
|
|
|
|
|
|
config_load upnpd
|
|
|
|
config_get iface config external_iface
|
2008-12-25 03:25:13 +00:00
|
|
|
|
2009-01-14 23:18:45 +00:00
|
|
|
[ -n "$INTERFACE" -a "$INTERFACE" != "$iface" ] && return
|
2008-12-25 03:25:13 +00:00
|
|
|
|
2009-01-14 23:18:45 +00:00
|
|
|
logger -t "upnp firewall" "removing wan interface"
|
2008-12-25 03:25:13 +00:00
|
|
|
|
2009-01-14 23:18:45 +00:00
|
|
|
upnp_ipt -t nat -D prerouting_rule -j miniupnpd_${iface:-wan}_rule
|
|
|
|
upnp_ipt -t nat -F miniupnpd_${iface:-wan}_rule
|
|
|
|
upnp_ipt -t nat -X miniupnpd_${iface:-wan}_rule
|
|
|
|
|
|
|
|
upnp_ipt -t filter -D forwarding_rule -j miniupnpd_${iface:-wan}_rule
|
|
|
|
upnp_ipt -t filter -F miniupnpd_${iface:-wan}_rule
|
|
|
|
upnp_ipt -t filter -X miniupnpd_${iface:-wan}_rule
|
2008-12-25 03:25:13 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
upnp_firewall_start() {
|
2009-01-14 23:18:45 +00:00
|
|
|
upnp_ipt -t nat -N MINIUPNPD
|
|
|
|
upnp_ipt -t filter -N MINIUPNPD
|
|
|
|
upnp_firewall_addif
|
2008-12-25 03:25:13 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
upnp_firewall_stop() {
|
2009-01-14 23:18:45 +00:00
|
|
|
upnp_firewall_delif
|
2008-12-25 03:25:13 +00:00
|
|
|
upnp_ipt -t nat -F MINIUPNPD
|
|
|
|
upnp_ipt -t nat -X MINIUPNPD
|
|
|
|
upnp_ipt -t filter -F MINIUPNPD
|
|
|
|
upnp_ipt -t filter -X MINIUPNPD
|
|
|
|
}
|